Nathan
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Nathan is a threat actor known by the alias Nathan and is reported to be based in the United Kingdom. The actor came to public attention through a single incident in which they gained unauthorized access to the mailing list of the retailer TOMS Shoes. No additional details of any broader affiliation or group membership have not been disclosed in the available sources. The actor’s identity beyond the alias remains unverified in open reporting.
In the October 2019 incident Nathan used the compromised TOMS Shoes mailing list to distribute a message urging recipients to step away from digital screens and engage with the physical world. The communication explicitly criticized other hackers who profit from selling personal data, describing such behavior as harmful and unethical. Nathan also expressed regret to TOMS Shoes for the intrusion, asking the company not to hold hard feelings. The content of the message indicates that the actor’s stated objective was to promote a social commentary on screen usage and to condemn malicious hacking practices rather than to pursue financial gain or espionage.
TOMS Shoes confirmed the unauthorized activity, noting that the breach affected its email and social media channels and advising customers to avoid interacting with the suspicious communication. The retailer stated it was investigating the matter and emphasized that no links or replies should be engaged with. Nathan claimed the intrusion was easy to execute but did not disclose the specific technique, tools, or malware employed. No details regarding initial access vectors, persistence mechanisms, or payloads were provided in the reporting.
Because the source material does not describe any additional campaigns, tooling, or affiliations, no further technical or operational characteristics can be attributed to Nathan. The actor’s known activity is limited to the single, publicly reported action against TOMS Shoes, which was framed as a message‑driven incident rather than a financially or strategically motivated operation. No public attribution to a state sponsor, criminal consortium, or other threat‑actor group has been made. This summarizes the currently verified facts about the threat actor Nathan.
Incidents
Attributed incidents are available to members.
1 incident